acme.sh - sponsored and maintained by ZeroSSL since 2021
You landed here because acme.sh never had a dedicated website, this is its new home. If you need to access the Github repository, click on one of the links below.
The certificate lifecycle is speeding up - acme.sh keeps you ahead of it.
With certificate lifetimes shrinking to 47 days, manual renewal isn't an option anymore. acme.sh, sponsored and maintained by ZeroSSL, is the automation layer built for that reality β from flexible DNS validation to renewal timing the certificate authority itself controls.
It's free. No credit card required.
Why do we sponsor acme.sh?
ZeroSSL is the default certificate authority for acme.sh, making it one of the most widely used integrations for automated SSL certificate management. By sponsoring the project, ZeroSSL ensures long-term reliability, compatibility, and continuous improvement for the global ACME ecosystem. This partnership provides users with a seamless experience, from issuing certificates to maintaining them at scale.
Certificate validity periods are shrinking
With certificate lifetimes on track to hit 47 days, manual renewal isn't sustainable anymore. acme.sh, sponsored and maintained by ZeroSSL, is a lightweight, fully automated ACME client built for exactly this shift β pure shell script, no dependencies, and no root access required.
acme.sh handles the entire certificate lifecycle end-to-end, from issuance to renewal, and gives you the flexibility to adapt as validation and CA requirements evolve.
- ARI (ACME Renewal Information) support, the CA tells the client the ideal renewal time, not the other way around
- Cron-based automated renewals, checked every 6 hours
- Account key rollover without re-registering or new credentials
- Built to handle renewal cycles as short as 47 days.
Simplified Certificate Management
acme.sh is a lightweight, fully automated ACME client that allows you to issue, install, and renew SSL/TLS certificates with minimal setup. Built as a pure shell script, it integrates seamlessly into existing workflows and infrastructure without adding complexity.
With native support for ZeroSSL, acme.sh enables developers and system administrators to automate certificate management end-to-end, from verification to deployment. Designed for simplicity and flexibility, acme.sh provides everything needed to manage SSL certificates at scale. It works across environments, supports multiple validation methods, and automates the entire certificate lifecycle.
- Automatic SSL/TLS certificate issuance and installation
- Flexible DNS validation - alias mode, account-based challenges for 180+ DNS providers, plus standard HTTP validation
- Wildcard + multi-domain support via DNS-01
- Zero dependencies - pure POSIX shell, runs on Linux, macOS, BSD, and containers
Buying SSL certs standalone is a thing from the past.
We're not in 2016 anymore, ZeroSSL pioneered Certificate as a Service in its inception year 2020. One subscription. Every cert you'll ever need.
β Native ZeroSSL integration out of the box
β Works with any ACME-compliant CA - never locked in
β Improved compatibility across servers and environments
β Long-term investment in automation and security standards
Γ Buy a single cert, repeat multiple times per year
Γ Overpay for multi-year SSL deals
Γ Per-domain pricing that doesn't scale
Γ Vendor lock-in with opaque pricing
acme.sh is well known and used by the biggest companies in the PKI space. Keyfactor CLM, Amazon Certificate Manager (ACM) and Sectigo Certificate Manager (SCM) Pro to name a few.
Key Features
Four qualities explain why acme.sh has become the default choice for certificate automation.
-
Lightweight
A pure Unix shell script for ACME certificate automation β any environment, fast execution, minimal dependencies.
-
Versatile
Supports multiple CAs, DNS APIs, and automation workflows used across Linux servers, DevOps pipelines, and CI/CD environments.
-
Trusted Everywhere
Used by millions of developers and recommended by leading security organizations.
-
Free & Open Source
MIT-licensed and free to use for any project, from personal sites to enterprise infrastructure β no vendor lock-in, ever.
acme.sh supports DNS alias mode, letting you delegate the challenge to a separate domain (e.g. a fresh Cloudflare account) so you never touch your legacy registrar's API directly. It also supports the newer account-based DNS challenge, which lets validation persist across renewals without repeating DNS changes every time.
Support for ARI (ACME Renewal Information) means the certificate authority tells the client the ideal renewal window instead of guessing β backed by 6-hour cron checks for hands-off automation.
Account key rollover lets you rotate your ACME account's signing key without creating a new account or new credentials, keeping your certificates and ZeroSSL binding fully intact.
Full wildcard and multi-domain issuance via the DNS-01 challenge method.
How does acme.sh compare?
Those features are only half the story β how they hold up against the most common alternative matters just as much. Certbot remains the default entry point for many teams, and for good reason: it was built by the same team that created the ACME protocol and Let's Encrypt itself, back in 2015, and has been the default recommendation ever since.
That head start explains its popularity, but for anything beyond the basics, the differences add up quickly.
How does acme.sh compare?
Those features are only half the story β how they hold up against the most common alternative matters just as much. Certbot remains the default entry point for many teams, and for good reason: it was built by the same team that created the ACME protocol and Let's Encrypt itself, back in 2015, and has been the default recommendation ever since. That head start explains its popularity, but for anything beyond the basics, the differences add up quickly.
| Feature | ||
|---|---|---|
| Zero dependencies | Pure shell script, meaning it runs anywhere: routers, containers, minimal Linux distributions. | Certbot's full Python runtime. |
| No root required | Install and run acme.sh as any user. | Certbot typically needs elevated privileges. |
| TLS-ALPN-01 support | acme.sh supports validation over port 443, useful when port 80 is blocked or DNS API access isn't available. | Not supported. |
| Broader DNS automation | Native support for 180+ DNS providers for hands-off wildcard and multi-domain issuance. | 40+ DNS providers. |
| CA flexibility | Works with any ACME-compliant certificate authority, so you're never locked into one provider. | Same. |
| CA independence & resilience | acme.sh is CA-agnostic by design. Run ZeroSSL as your primary, a second CA as a hot fallback, and a regional CA for compliance β all from the same tool, no forking, no emergency scramble. | CA-agnostic by configuration. |
Certbot
Certbot
Certbot
Certbot
Certbot
CertbotFrequently Asked Questions
Common questions about ZeroSSL & acme.sh we often get.
SSL/TLS certificates are now short-lived by design, requiring frequent renewal to maintain security. Automation ensures your certificates are always valid, preventing outages and ensuring continuous HTTPS protection across all your domains.
Missed renewals lead to expired certificates, browser warnings, and lost user trust. With ZeroSSL ACME automation, certificates are issued and renewed automatically in the background, eliminating manual errors and downtime risk.
The ACME protocol connects your infrastructure directly to ZeroSSL, enabling automated domain validation, certificate issuance, and renewal without manual interaction. This allows you to scale SSL management effortlessly across projects and environments.
ZeroSSL offers free ACME-based 90-day certificates, ideal for most standard use cases.
For advanced needs such as higher issuance volumes, extended certificates, or business-critical infrastructure, ZeroSSL paid plans provide additional flexibility, limits, and support.
ZeroSSL is deeply integrated with acme.sh and other ACME clients, offering:
β Free, automated certificate issuance
β Broad compatibility across environments
β A clear upgrade path to scalable paid plans
This makes ZeroSSL suitable for both individual developers and enterprise deployments.
As infrastructure grows across servers, containers, and dynamic domains, manual SSL management becomes impractical. With acme.sh and ZeroSSL, you can centrally automate certificate lifecycle management while upgrading to paid plans when higher scale, performance, or support is required.
Certificate lifetimes have been shrinking fast β from 398 days, to 200, to 90, heading toward 47. If your infrastructure isn't automated yet, you're already behind, not preparing for the future. ZeroSSL has built and funded acme.sh for six years for exactly this moment β free to use, and paired with our own certificates starting at just $9.99/month, so individuals, small teams, and enterprises alike have no excuse left to wait.
Questions answered? Here's how to get started with ZeroSSL & acme.sh.
Start automating with ZeroSSL
Get ready to automate your SSL certificate needs.
ZeroSSL offers fast issuance, ACMEβfirst workflows, and globally trusted certificate management. Combine our expertise in PKI with the most well known and public trusted ACME client.
#1 trusted ACME client
acme.sh is the most widely used ACME client, trusted by developers and infrastructure teams worldwide. With 40k+ GitHub stars and broad real-world adoption, it has become the go-to solution for automated SSL/TLS certificate management.